ASD ISM 1634System Owners Select and Tailor Controls in Consultation with Authorising Officer
Official control statement
System owners, in consultation with each system's authorising officer, select security controls for each system and tailor them to achieve desired security and resilience objectives.
Quoted as published. Everything else on this page is written by Control Stack.
In plain English
Each system's owner works with its authorising officer to choose the security controls that apply and adjust them so the system meets its security and resilience goals.
What this means in practice
Every system is different, so a one-size-fits-all list of security controls rarely fits well. This control makes the system owner responsible for deciding which security controls apply to their system and for tailoring those controls (adding, strengthening, scaling back or adapting them) so the system actually achieves the security and resilience outcomes the organisation wants from it. Critically, the system owner does not do this alone: the selection and tailoring must be worked through in consultation with the system's authorising officer, the person who will ultimately accept the risk of the system operating. Why it matters: if controls are picked without thought for the system's purpose, data, threats and environment, you end up with gaps (important controls missing or watered down) or wasted effort (controls that add cost and friction but little protection). Bringing the authorising officer into the decision early means the person accepting the residual risk understands what has been selected, what has been tailored and why, rather than discovering surprises at authorisation time. The result is a control set that is deliberate, justified and aligned to what the system needs to withstand and recover from.
Framework
ASD Information Security Manual (ISM)
Control effect (Control Stack)
Proactive
Classifications
NC, OS, P, S, TS
ISM last updated
Sept 2026
Control Stack last updated
29 Sept 2026
E8 maturity levels
N/A
Guideline
Guidelines for cyber security rolesSection
System ownersTopic
Protecting systems and their resources
Why it matters
Without deliberate selection and tailoring, systems either inherit generic control sets that leave real threats unaddressed or carry controls that do not fit and get quietly bypassed. Security and resilience objectives go unmet, weaknesses persist into production, and incidents become more likely and harder to recover from. If the authorising officer was not consulted, they may authorise a system on an inaccurate picture of its protections, accept risk they never understood, or refuse authorisation late in the project, causing rework and delays.
Operational notes
In practice this control runs at the start of a system's life-cycle and again whenever the system changes materially. The system owner starts from the organisation's applicable control baseline, then works through each control asking whether it applies, whether it needs to be strengthened, relaxed, replaced or supplemented, and how it contributes to the system's stated security and resilience objectives. Each decision is recorded with its reasoning.
The authorising officer is consulted throughout, not just at sign-off. Typical touchpoints are an initial scoping discussion to agree objectives, a review of the proposed tailored control set, and confirmation of any controls being scaled back or not implemented. Keep the tailored control set as a living document: when the system's purpose, data, hosting or threat environment shifts, the system owner revisits the selection with the authorising officer and updates the record. Make sure the people who implement and operate the system are working from the tailored set, not a generic template.
Implementation tips
- System owners define and write down the security and resilience objectives for their system (what it must protect, what it must keep doing under stress, and how quickly it must recover) before selecting any controls, and confirm those objectives with the authorising officer.
- System owners take the organisation's applicable control baseline and produce a system-specific control selection, marking each control as applicable, tailored or not applicable, with a one-line justification per decision.
- System owners hold a structured consultation with the authorising officer to walk through the proposed control set, focusing discussion on tailored and excluded controls, and capture the officer's input and any agreed changes in minutes or a decision log.
- System owners maintain a tailored control register (or system security plan section) that records the final selected controls, how each was tailored, the objective it supports and the date the authorising officer was consulted, and publish it to the implementation and operations teams.
- System owners schedule a re-selection review whenever the system undergoes a significant change (new data types, new hosting, new integrations, new threats) and repeat the consultation with the authorising officer so the tailored control set stays current.
Audit / evidence tips
- AskAsk for the documented security and resilience objectives for a sample of systems.Look atCheck that objectives are specific to each system rather than copied boilerplate, and that the authorising officer agreed to them.GoodEach sampled system has clear, system-specific objectives that the control selection visibly references.
- AskRequest the tailored control selection or system security plan for each sampled system.Look atLook for every control in the baseline being marked applicable, tailored or not applicable, with a reason recorded for each tailored or excluded control.GoodDecisions are complete, justified and traceable to the system's objectives, with no unexplained gaps.
- AskAsk for evidence that the authorising officer was consulted on the control selection and tailoring.Look atReview meeting minutes, decision logs, emails or sign-off records for the authorising officer's involvement, especially on scaled-back or excluded controls.GoodThe record shows the authorising officer engaged during selection and tailoring, not only at final authorisation.
- AskAsk who the system owner and authorising officer are for each sampled system and how those roles are assigned.Look atConfirm the named individuals match those who appear in the selection and consultation records.GoodRoles are clearly assigned and the people in those roles are the ones who actually made and consulted on the decisions.
- AskAsk how tailored control sets are kept current after system changes.Look atLook for evidence that a recent significant change triggered a re-selection review and a fresh consultation with the authorising officer.GoodControl selections are revisited after material change, with updated records and renewed authorising officer input.
Cross-framework mappings
How ISM-1634 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(1)expand_less | ||
| Annex A 8.26 | ISM-1634 requires system owners, in consultation with the authorising officer, to select and tailor security controls for each system to ... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Cyber security roles
See all Guidelines for cyber security roles controls, or browse the full ASD ISM library.